← Back

CVE-2020-1690

nvd nist
Published: Jun 7, 2021Modified: Nov 21, 2024

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
Exploitability: 2.0 / Impact: 4.0
Source: NVD

Description

An improper authorization flaw was discovered in openstack-selinux's applied policy where it does not prevent a non-root user in a container from privilege escalation. A non-root attacker in one or more Red Hat OpenStack (RHOSP) containers could send messages to the dbus. With access to the dbus, the attacker could start or stop services, possibly causing a denial of service. Versions before openstack-selinux 0.8.24 are affected.

Affected (3)

2 products
Openstack Selinux
Openstack Platform
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 0.8.24
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
Redhat
Version 15.0
Version 16.1

References (2)

Source: secalert@redhat.com
Issue TrackingVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingVendor Advisory

Timeline

No history available yet.